Public-key infrastructure validation and revocation mechanism suitable for delay/disruption tolerant networks

Muhammad Nasir Mumtaz Bhutta, H. Cruickshank, Zhili Sun
{"title":"Public-key infrastructure validation and revocation mechanism suitable for delay/disruption tolerant networks","authors":"Muhammad Nasir Mumtaz Bhutta, H. Cruickshank, Zhili Sun","doi":"10.1049/iet-ifs.2015.0438","DOIUrl":null,"url":null,"abstract":"Public-key infrastructure (PKI) is based on public-key certificates and is the most widely used mechanism for trust and key management. However, standard PKI validation and revocation mechanisms are considered major reasons for its unsuitability for delay/disruption tolerant networking (DTN). DTN requires mechanism to authenticate messages at each node before forwarding it in the network. So, certificate revocation lists (CRLs) being distributed in DTN network will need to be authenticated and validated for issuer certificate authority (CA) at each node. In this study, the authors propose new validation and revocation mechanism which is compliant with DTN semantics and protocols. This study also proposes a new design for CRL in compliance with standard PKI X.509 standard to make the proposed mechanism easy to implement for DTN. The new designed CRL is of reduced size as it contains fewer entries as compared with standard X.509 CRL and also arranges the revocation list in the form of hash table (map) to increase the searching efficiency.","PeriodicalId":13305,"journal":{"name":"IET Inf. Secur.","volume":"114 24","pages":"16-22"},"PeriodicalIF":0.0000,"publicationDate":"2017-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IET Inf. Secur.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1049/iet-ifs.2015.0438","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

Abstract

Public-key infrastructure (PKI) is based on public-key certificates and is the most widely used mechanism for trust and key management. However, standard PKI validation and revocation mechanisms are considered major reasons for its unsuitability for delay/disruption tolerant networking (DTN). DTN requires mechanism to authenticate messages at each node before forwarding it in the network. So, certificate revocation lists (CRLs) being distributed in DTN network will need to be authenticated and validated for issuer certificate authority (CA) at each node. In this study, the authors propose new validation and revocation mechanism which is compliant with DTN semantics and protocols. This study also proposes a new design for CRL in compliance with standard PKI X.509 standard to make the proposed mechanism easy to implement for DTN. The new designed CRL is of reduced size as it contains fewer entries as compared with standard X.509 CRL and also arranges the revocation list in the form of hash table (map) to increase the searching efficiency.
适用于延迟/中断容忍网络的公钥基础设施验证和撤销机制
公钥基础设施(Public-key infrastructure, PKI)基于公钥证书,是使用最广泛的信任和密钥管理机制。然而,标准的PKI验证和撤销机制被认为是其不适合延迟/中断容忍网络(DTN)的主要原因。DTN要求在每个节点上对消息进行身份验证,然后再在网络中转发。因此,在DTN网络中分发的证书撤销列表(crl)需要在每个节点上为颁发者证书颁发机构(CA)进行身份验证和验证。在这项研究中,作者提出了一种新的符合DTN语义和协议的验证和撤销机制。本研究还提出了一种符合标准PKI X.509标准的CRL新设计,使所提出的机制易于DTN实现。与标准的X.509 CRL相比,新设计的CRL的大小更小,因为它包含的条目更少,并且还以哈希表(map)的形式排列吊销列表,以提高搜索效率。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信